Improper initialization in Linux kernel - CVE-2026-90094
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause MTE store-only tag check state to leak into another task.
The vulnerability exists due to improper restoration of SCTLR_EL1.TCSO0 state in arm64 context switching when switching from a task that has opted into MTE store-only tag check mode. A local user can opt into MTE store-only tag check mode and trigger a context switch to cause MTE store-only tag check state to leak into another task.